PT-2009-3598 · Bea+1 · Bea Weblogic Server+2

Publicado

2009-04-15

·

Atualizado

2025-09-08

·

CVE-2009-1016

CVSS v2.0

8.5

Alta

VetorAV:N/AC:M/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions BEA Product Suite versions 7.0 SP7 through 10.3 BEA WebLogic Server version 8.1 SP6 BEA WebLogic Server versions 9.0 through 9.2 MP3
Description The issue affects confidentiality, integrity, and availability, and is related to IIS. It may involve a stack-based buffer overflow related to an unspecified Server Plug-in and a crafted SSL certificate.
Recommendations For BEA Product Suite versions 7.0 SP7 through 10.3, consider restricting access to the Server Plug-in to minimize the risk of exploitation. For BEA WebLogic Server version 8.1 SP6, avoid using crafted SSL certificates until the issue is resolved. For BEA WebLogic Server versions 9.0 through 9.2 MP3, as a temporary workaround, consider disabling the use of SSL certificates in the Server Plug-in until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2009-1016

Produtos afetados

Bea Product Suite
Bea Weblogic Server
Iis